Privacy Policy

Effective date: 1 June 2026  ·  Version 1.0  ·  Applies to: crm.todahsystems.com

Summary: We collect only what is needed to run your CRM workspace. We do not sell your data. You can export or delete your data at any time by contacting us. This policy complies with the Nigeria Data Protection Regulation (NDPR) and the EU General Data Protection Regulation (GDPR).

1. Who We Are

Data Controller & Processor: Todah Systems Limited (trading as OppTrack CRM), Lagos, Nigeria.

Contact: privacy@todahsystems.com

Data Protection Officer: [DPO Name] — dpo@todahsystems.com

We operate OppTrack CRM, a cloud-based customer relationship management platform available at crm.todahsystems.com.

2. Scope

This policy applies to:

As a B2B SaaS product, Tenants are the Data Controllers of the personal data they enter about their customers. Todah Systems acts as the Data Processor for that data. For Tenant account data, we act as Data Controller.

3. Data We Collect

3.1 Account & Registration Data

3.2 Data Entered by Tenants (CRM Data)

Tenants enter their own business data into the platform, which may include personal data about their clients and contacts:

3.3 Technical & Usage Data

4. Lawful Basis for Processing

Data CategoryLawful Basis (GDPR Art. 6)NDPR Basis
Account registration dataContract (Art. 6(1)(b)) — necessary to provide the serviceContractual necessity
Billing and plan dataContract (Art. 6(1)(b))Contractual necessity
CRM data entered by TenantsLegitimate interests of the Tenant (Art. 6(1)(f)); consent where requiredLegitimate interest / consent
Security & audit logsLegitimate interests (Art. 6(1)(f)) — fraud prevention, securityLegitimate interest
Session cookiesStrictly necessary — consent exception appliesStrictly necessary

5. How We Use Your Data

We do not use your CRM data for advertising, profiling, or sale to third parties.

6. Sub-Processors and Third Parties

We use the following sub-processors. Each is bound by a Data Processing Agreement:

Sub-ProcessorPurposeData TransferredLocation
DigitalOcean, LLCCloud hosting and database storageAll platform dataUnited States / EU (configurable)
Brevo (Sendinblue)Transactional email deliveryEmail address, name, message contentEuropean Union

We do not share your data with any other third party except where required by law.

7. Cookies

We use one strictly necessary cookie:

Cookie NamePurposeDurationType
PHPSESSIDSession authentication — keeps you logged inBrowser session (deleted on close)Strictly necessary

We do not use tracking cookies, advertising cookies, or analytics cookies. No third-party cookies are set by our platform.

8. Data Retention

Data TypeRetention Period
Active tenant workspace dataFor the duration of the subscription + 30 days after cancellation
Audit and activity logs2 years
Login attempt records24 hours
Password reset tokens1 hour (auto-expired)
Erasure request records5 years (legal compliance)

9. Your Rights

Under GDPR and NDPR, you have the following rights:

To exercise any of these rights, contact us at privacy@todahsystems.com. We will respond within 30 days.

10. Cross-Border Data Transfers

Data is stored on DigitalOcean servers. For EU users, you may request data storage on EU-region servers. Transfers outside the EEA are covered by Standard Contractual Clauses (SCCs) as per GDPR Chapter V.

For Nigerian users: data stored outside Nigeria is governed by NDPR provisions on cross-border transfers. We take appropriate steps to ensure equivalent protection.

11. Security

We implement the following technical measures:

12. Data Breach Notification

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware (GDPR Art. 33) and notify affected data subjects without undue delay where there is a high risk to their rights and freedoms.

To report a security vulnerability: security@todahsystems.com

13. Children's Data

OppTrack CRM is a business product intended for use by organisations. We do not knowingly collect personal data from children under 13. If you believe a child's data has been submitted, contact us immediately.

14. Changes to This Policy

We may update this policy. Material changes will be notified by email to account holders at least 14 days before taking effect. The version number and effective date at the top of this page always reflect the current policy.

15. Complaints

You have the right to lodge a complaint with your local data protection authority: